Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Policy Enforcement Tools | Main | Will Cybercrime Break the Internet? »

Soft Breaches and Intellectual Property Theft at Oracle

Oracle is suing its rival SAP over alleged theft of intellectual property, specifically tens of thousands of support documents made available to Oracle customers.

Intelligent Enterprise is reporting:

Oracle makes that charge against its archrival, claiming in a civil lawsuit filed last week that SAP employees pretended to be Oracle customers to log on to one of the company's Web sites and copy proprietary technical and customer-support data. Describing SAP's actions as "corporate theft on a grand scale," Oracle claims that SAP gathered the support documentation to provide cut-rate support for Oracle products, then shift those companies to SAP products.

The take away from this is data breaches aren't just coming from hackers breaking into databases looking for identity or financial data. With enough documents, a rival can piece together an impressive library of competitive intelligence information about your company. The question is how to detect this?

Monitoring network traffic can alert you to unusual traffic to a single site. If one customer is downloading unusually large numbers of documents or Web pages, it could be an indication of intelligence gathering. This may not be illegal (or in some cases, as Oracle alleges, it is) but you should at least be aware of who is pulling down large volumes of content. Why they do it isn't something the network monitor will tell you.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/262

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net